# Every install network dies the same way

> The desktop cross-promotion category has a graveyard, and the causes of death are not mysterious. Three mechanisms, each individually reasonable, combine into an incentive structure whose profitable endpoint is software people did not choose. Removing any one of the three breaks the chain.

Source: https://ghan.io/blog/why-install-networks-die/  
Published: 2026-09-20 · Updated: 2026-09-22  
Publisher: GHAN — the audited cross-promotion network for desktop apps (https://ghan.io)

---

## Three mechanisms

### 1. The offer lives inside the installer

An installer is a sequence of screens whose only purpose is to be clicked through. The person has already decided; they are executing. A third-party offer placed in that sequence competes for the same reflexive click as Next.

That means every increment of ambiguity between "continue" and "accept" is worth money. Not because anyone set out to deceive, but because A/B testing finds it. The variant that converts better is the one that is slightly less clear, and the process runs until the offer is indistinguishable from a system dialog.

There is no equilibrium here where maximum clarity is also maximum revenue.

### 2. The money clears on the install event

If payment happens the moment software lands on a disk, then retention, satisfaction and relevance are all somebody else's problem. A brilliant match and a mistaken click pay identically.

A rational publisher facing that rule optimises for the number of things that land, and the cheapest way to increase that number is never better targeting.

### 3. The partner supplies the creative

A network that transmits arbitrary partner content is a distribution channel for arbitrary partner content. Whatever the review process, the pressure runs one direction: big advertisers want custom treatments, custom treatments look more native, more native converts better, and eventually the thing being distributed is not an advertisement.

## How it ended

Antivirus vendors do not evaluate intent. They classify behaviour, and the behaviour — software arriving on machines through an install flow the person did not deliberately choose — is the behaviour of a potentially unwanted program.

Crucially, the classification attaches to the **SDK**, not to individual offers. So the honest integrator who carefully explained every offer got flagged alongside the worst actor in the network. By 2015 that was most of the category. OpenCandy shut down in 2016. AdDuplex, the cleanest attempt, shut down quietly in 2023.

The lesson usually drawn — "desktop cross-promotion does not work" — is the wrong one. The correct lesson is that those three mechanisms do not work, and every one of them is optional.

## What removing them costs

Removing them is not free, which is why nobody did.

- **No installer placement** means giving up the highest-volume, highest-attention inventory on desktop.
- **No payment on the event** means the network carries 48 hours of settlement risk and reports lower conversion numbers than a competitor who does not.
- **No partner creative** means losing every advertiser whose brand team requires control, which is most large advertisers.

A network that removes all three has worse unit economics on day one than one that does not. It only wins if the thing it is selling is trust, and trust only becomes a product if it is checkable.

## Checkable, specifically

Promising to behave is what the previous generation also did. The difference has to be structural:

- The unit of billing requires two independent cryptographic signatures, one of which is produced inside the advertiser's own signed binary.
- The ledger blocks edits at the database level, so corrections are new lines and history survives.
- The gate is automated, published, and re-run weekly rather than at onboarding.
- Rejection numbers are published, because a network reporting zero fraud is reporting on its own detection, not on reality.

None of those are promises. They are properties a partner's agent can verify without the network's cooperation, which is the only kind of trust claim that survives revenue pressure.

That is what [GHAN](/) is, and the constraints on its [lifecycle slots](/lifecycle-slots/) and its [fraud rules](/fraud-prevention/) are each traceable to one of the three mechanisms above.

## Questions people ask about this

### What killed OpenCandy?

The combination of placing an offer inside an installer and paying on the install event. Individually each is defensible. Together they make accidental acceptance the most profitable outcome, and there is no stable point at which the clearest possible presentation is also the best-earning one. Antivirus vendors classified the resulting behaviour correctly, and the classification attached to the SDK rather than to individual offers.

### Can a cross-promotion network be safe?

Yes, if the three mechanisms are removed rather than moderated. No placement inside an installer. No payment on the install event. No partner-supplied creative. A network that keeps any of the three and promises to behave has only moved the failure from its design into its governance, and governance is exactly what degrades under revenue pressure.

